AIR launches with $50M to secure the AI agent supply chain
By admin | Sep 01, 2026 | 4 min read
As companies increasingly grant AI agents broader access to their systems, a new kind of software supply chain is quietly taking shape. This emerging ecosystem revolves around the tools these agents rely on—skills, plugins, MCP servers, and add-ons that enable them to interact with the internet. AIR, an AI security startup, believes organizations will need a way to keep tabs on this supply chain, and it's stepping out of stealth mode with $50 million raised across two seed rounds to build exactly that.
The company was founded by Yair Saban (CEO) and Niv Hoffman (CTO), both veterans of Israel's Unit 8200 intelligence corps, where they focused on offensive cybersecurity. AIR's platform is designed to discover agents running within a company, continuously vet the skills, tools, and components those agents use, and block interactions with software or external sources that fail to meet security standards. It also operates a marketplace of pre-vetted add-ons and skills for AI agents. Sequoia led the first funding round, while Greenoaks led the second, according to Saban. Additional participants included Swish, Netz, and a roster of angel investors such as Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Erlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay), and others.
AIR's core argument is that the way AI agents are deployed across companies is starting to resemble operating systems, yet the tools they use or the software they can install haven't received the same level of oversight we apply to drivers or applications. Saban draws a parallel to the early 2000s: "Back then, when you installed a driver, it didn't need to be signed. Today, every driver you install comes with a signature showing who created it, because that driver is loading code directly into the kernel," he explained. "We don't have that with skills, plugins, or MCPs, and that's a problem—it's the same mechanism, the same lesson, but we haven't applied it."
The primary risk, he argues, is that as AI agents operate more autonomously across databases, enterprise systems, and internet connections, attackers can poison the content an agent consumes rather than attacking it head-on. AIR says it addresses this with a visibility product that identifies agents active across a company's environment, along with employees using unapproved AI tools or personal accounts. It then deploys an enforcement layer that hooks into agents to intercept and analyze actions—like loading a skill or fetching content from the web. Finally, AIR cross-references the tools, add-ons, or software an agent wants to use against a whitelist maintained by the startup. Saban says this whitelist is kept current by continuously evaluating openly available skills and add-ons for changes or malicious behavior, since a previously approved skill could become risky if a dependency shifts or a developer's account gets compromised. He added that AIR's platform currently filters out about 27% of the add-ons and skills it discovers online.
AIR reports having more than 20 customers, with roughly a quarter of them being large enterprises. Saban noted that demand has been strongest in heavily regulated sectors, particularly financial services and pharmaceuticals. That said, AIR isn't alone in this space. Noma Security provides discovery, access controls, and runtime monitoring for agents, MCP servers, and skills, while Zenity sells similar security and governance tools. Astrix Security's identity platform also enables companies to discover and control agents and MCP servers, and Operant AI offers agent protections along with an MCP gateway. The category is attracting significant venture investment as well: Zenity raised a $125 million Series C in August, and Noma secured a $100 million Series B last year.
Saban believes AIR's competitive edge lies in its ability to continuously vet the growing ecosystem of skills and add-ons around AI agents. "Continuously vetting skills and plugin websites is a hard mission. Gaining visibility over the endpoint is easy—everyone's going to do that. It's hard to create a moat around that," he said. While he acknowledges that AI labs and providers will eventually build in their own security checks and policies to filter out malicious tools, he thinks companies will still prefer an independent product that works across multiple vendors. "Inspecting every skill, plugin, MCP server, and sub-agent an enterprise's agents touch, re-inspecting each one every time it changes, in real time and across an entire company's agent fleet, is an infrastructure problem long before it is a security problem. AIR has spent the last year building that pipeline. You don't catch up to it by writing a better scanner."
AIR currently employs around 40 people. Saban said the new funding will primarily go toward hiring researchers and expanding the company's go-to-market efforts in the U.S. and Europe.
Comments
Please log in to leave a comment.
No comments yet. Be the first to comment!